Tracing Vendors: A Middlebox-Centric Study of Network Interference

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

Abstract

Middleboxes are intermediary network devices that facilitate traffic monitoring, filtering, and modification. They serve a broad spectrum of functions, ranging from benign tasks to highly controversial ones such as censorship. A solid body of work exists that describes methods to probe or identify middleboxes from remote including censorship middleboxes; similarly, much research has gone into fingerprinting network devices. However, there is comparatively little work that aims to understand which type of devices occurs in which networks. In this study, we choose to investigate middleboxes that reside in networks reported for network interference. We use yarrpbox, a scanning tool, to detect middleboxes and map them to vendors utilizing third-party datasets. Covering more than 500 Autonomous Systems reported for interference, we identify about 250 middleboxes, which we study in detail. We find that the location of middleboxes across countries does not correlate to the Internet Freedom Index, and we identify a distribution of vendors as well as a distribution across countries that differs markedly from previous reports. Most middleboxes in the reported networks are actually likely to serve multiple purposes, and this complexity calls for new measurement methodologies to determine whether the reported interference is a byproduct of some configuration or the primary purpose of a middlebox. We also identify a number of security issues in a number of devices, lending further support for the hypothesis that middleboxes can increase the attack surface of a network. We conclude with a discussion of directions to understand middlebox deployment with further measurements.

Original languageEnglish
Title of host publication2025 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
Place of PublicationPiscataway, NJ
PublisherIEEE
Pages176-186
Number of pages11
ISBN (Electronic)979-8-3315-9546-3
ISBN (Print)979-8-3315-9547-0
DOIs
Publication statusPublished - 2025
Event10th IEEE European Symposium on Security and Privacy Workshops, EuroS&PW 2025 - Venice, Italy
Duration: 30 Jun 20254 Jul 2025
Conference number: 10

Publication series

NameProceedings - 10th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2025
PublisherIEEE
Volume2025
ISSN (Print)2768-0649
ISSN (Electronic)2768-0657

Conference

Conference10th IEEE European Symposium on Security and Privacy Workshops, EuroS&PW 2025
Abbreviated titleEuroS&PW 2025
Country/TerritoryItaly
CityVenice
Period30/06/254/07/25

Keywords

  • 2025 OA procedure
  • Network Analysis
  • Network Interference
  • Vendor Mapping
  • Middleboxes

Fingerprint

Dive into the research topics of 'Tracing Vendors: A Middlebox-Centric Study of Network Interference'. Together they form a unique fingerprint.

Cite this